SaaS Ranking

security.txt (RFC 9116) in Coding assistants

It tells a researcher where to report a vulnerability instead of guessing.

7 of 16 vendors we measured here publish it, that is 44%. Last checked 2026-09-06.

44% here against 12% across every category we measure. Coding assistants sits above the overall share for this criterion.

Back to security.txt (RFC 9116) across all categories, or to Coding assistants.

Published

Served at /.well-known/security.txt.

VendorWhat we found
Cline https://cline.bot/.well-known/security.txt
Cursor https://cursor.com/.well-known/security.txt
Kilo https://kilo.ai/.well-known/security.txt
Magic https://magic.dev/.well-known/security.txt
OpenHands https://www.openhands.dev/.well-known/security.txt
Poolside https://poolside.ai/.well-known/security.txt
Qodo https://www.qodo.ai/.well-known/security.txt

No security.txt found.

We reached at least one address for each of these vendors and none of them carried it. That is what we found at the addresses we checked, on the date we checked them, and not a statement about what the vendor has.

VendorWhat we found
Augment Code 1 address checked
CodeGPT 1 address checked
Cognition 1 address checked
Factory 1 address checked
Refact 1 address checked
Roomote 1 address checked
Tabnine 1 address checked
Trae 1 address checked
Zed 1 address checked

Not measured

We could not look at these, or their robots.txt asks us not to. That says something about our measurement, not about them, and they are left out of the percentage above.

None. Every vendor here was measured for this criterion.

Found something we missed? Tell us and the next run picks it up.